logo

Maestro & Unibot

ID: 42923727-0e5c-5df4-a6da-fd8ebbec19d7

STIX ID: report--42923727-0e5c-5df4-a6da-fd8ebbec19d7

Feed Name: CertiK Blog

Threat Score
70/100

Date Published: 2023-11-02

Date Updated: 2026-06-11

...
...

In late October, attackers exploited missing access control in the Maestro and Unibot Telegram trading bot router contracts to perform arbitrary external calls and invoke transferFrom on users' pre-approved ERC-20 tokens. The two incidents affected 106 users and resulted in roughly $1.1M in losses after stolen tokens were swapped for ETH; the underlying flaw was an unprotected router function lacking permission and parameter checks, and users are advised to regularly check and revoke unnecessary token approvals.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.